Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
12New in 24h
346PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11117 results

PoCs 1 ★ 3 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
FUNFACTOR1/CVE-2026-82090-18-Years-All-Versions-CVSS-9.2-CRITICAL-The-Pocket-Forever-Day

CVE-2026-82090 · CVSS 9.2 CRITICAL · 0-click stored XSS in Mozilla Pocket — all versions (v0 → v8.33.0.0) · 18-year forever-day · no patch · MITRE published

★ 3 · 2026-09-17
CVE-2021-3156
HOTMULTI PoC
PoCs 88 ★ 1025 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 8 of 88 repositories
blasty/CVE-2021-3156
★ 1025 · 2021-02-02
worawit/CVE-2021-3156

Sudo Baron Samedit Exploit

★ 807 · 2022-01-13
stong/CVE-2021-3156

PoC for CVE-2021-3156 (sudo heap overflow)

★ 428 · 2022-04-14
LiveOverflow/pwnedit

CVE-2021-3156 - Sudo Baron Samedit

★ 227 · 2022-02-12
Rvn0xsy/CVE-2021-3156-plus

CVE-2021-3156非交互式执行命令

★ 203 · 2021-02-09
CptGibbon/CVE-2021-3156

Root shell PoC for CVE-2021-3156

★ 158 · 2022-02-13
reverse-ex/CVE-2021-3156

CVE-2021-3156

★ 112 · 2021-01-31
0x4ndy/clif

clif is a command-line interface (CLI) application fuzzer, pretty much what wfuzz or ffuf are for web. It was inspired by sudo vulnerability CVE-2021-3156 and …

★ 100 · 2022-12-22
PoCs 1 ★ 1 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
SneakyNachos/CVE-2026-85045
★ 1 · 2026-09-17
PoCs 1 ★ 6 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
lcf2212dev/image-size-next

Community-maintained fork of image-size with fixes for CVE-2025-71329 and CVE-2025-71330

★ 6 · 2026-09-17
PoCs 4 ★ 2 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 4 repositories
0xBlackash/CVE-2026-76461

CVE-2026-76461

★ 2 · 2026-09-15
S3v3n-JG/CVE-2026-76461

CVE-2026-76461

★ 1 · 2026-09-17
HORKimhab/CVE-2026-76461

CVE-2026-76461 - Draft or TODO

★ 0 · 2026-09-15
PoCs 1 ★ 2 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
S3v3n-JG/CVE-2026-76460

CVE-2026-76460

★ 2 · 2026-09-17
PoCs 2 ★ 1 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 2 repositories
LoserLab/bigint-buffer-safe

Safe, pure-JS drop-in replacement for bigint-buffer. Fixes CVE-2025-3194 (CVSS 7.5). Zero dependencies, no native bindings.

★ 1 · 2026-03-16
disley15-collab/bigint-buffer-js

Pure-JS drop-in for [email protected] without the vulnerable native binding (CVE-2025-3194)

★ 0 · 2026-09-17
PoCs 1 ★ 0 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
amanbahiniya/cve-disclosures

CVE-2024-57551, CVE-2024-57552, CVE-2024-57553 advisories by Aman Bahiniya

★ 0 · 2026-09-17
CVSS 6.5 MEDIUM CWE-284 Published 2026-09-19 PoCs 1 ★ 1 Last push 2026-09-17 (3 weeks, 2 days ago)

The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query identifier before storing a persisted query from a request, allowing unauthenticated users to publish arbitrary query documents and claim query aliases before a site's own frontend registers them.

Show 1 repositories
MS-0x404/CVE-2026-92099

PoC for CVE-2026-92099 on WPGraphQL Smart Cache

★ 1 · 2026-09-17
PoCs 1 ★ 0 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
HORKimhab/CVE-2026-19975

CVE-2026-19975 - Draft or TODO

★ 0 · 2026-09-17
PoCs 4 ★ 3 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 4 repositories
Gutierre0x80/CVE-2026-59827

Technical analysis and proof of concept for CVE-2026-59827, a critical unsafe Java deserialization vulnerability in Metabase leading to remote code execution.

★ 3 · 2026-08-12
pickl31/CVE-2026-59827

Metabase CVE-2026-59827 Vulnerability Scanner

★ 1 · 2026-07-23
c0gnit00/CVE-2026-59827

Blog on CVE-2026-59827, Unsafe H2 query ouput deserialization

★ 0 · 2026-07-15
shivammittal2403/cve-2026-59827-metabase-cyber-range

Educational cyber range for CVE-2026-59827 (Metabase H2 unsafe deserialization / CWE-502). Isolated Docker lab — training only, not for attacking production Me…

★ 0 · 2026-09-17
PoCs 1 ★ 1 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
0xSemizzz/CVE-2026-92162

CVE-2026-92162: Path traversal in the Flatpak system helper: an unvalidated arch parameter in DeployAppstream lets an active local user create root-owned direc…

★ 1 · 2026-09-17
PoCs 4 ★ 29 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 4 repositories
nokn0wthing/CVE-2023-20052

CVE-2023-20052, information leak vulnerability in the DMG file parser of ClamAV

★ 29 · 2023-05-08
cY83rR0H1t/CVE-2023-20052

CVE-2023-20052 information leak vulnerability in the DMG file parser of ClamAV

★ 0 · 2023-09-10
MOHITSINGHPAPOLA/CVE-2023-20052

Working Docker build for the ClamAV XXE exploit (CVE-2023-20052), patched to compile on OpenSSL 3.0

★ 0 · 2026-02-14
tralsesec/CVE-2023-20052

Original standalone Proof-of-Concept exploit and execution harness for CVE-2023-20052 (ClamAV DMG XML Entity Expansion).

★ 0 · 2026-09-17
PoCs 1 ★ 0 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
isaca0315/CVE-2026-44840-poc
★ 0 · 2026-09-17
CVE-2025-8061
HOTMULTI PoC
PoCs 5 ★ 125 Last push 2026-09-17 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 5 repositories
symeonp/Lenovo-CVE-2025-8061

PoC for popping a system shell against the LnvMSRIO.sys driver

★ 125 · 2025-10-06
spawn451/CVE-2025-8061-Exploit

Exploit LnvMSRIO.sys vulnerable driver

★ 18 · 2025-12-10
segura2010/lenovo-dispatcher-poc

PoC to exploit lenovo dispatcher driver (LnvMSRIO.sys) (CVE-2025-8061)

★ 4 · 2025-11-17
uLl0a/MSRMapper

MSRMapper is a manual kernel driver mapper for Windows x64 that abuses CVE-2025-8061 in the vulnerable Lenovo driver LnvMSRIO.sys to perform a BYOVD (Bring You…

★ 2 · 2026-09-17
vxqs/Lenovo-CVE-2025-8061

My PoC of Lenovo-CVE-2025-8061

★ 0 · 2026-04-26
CVE-2025-32432
MULTI PoC
PoCs 14 ★ 26 Last push 2026-09-17 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 8 of 14 repositories
Sachinart/CVE-2025-32432

This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerability affecting CraftCM…

★ 26 · 2025-04-27
Chocapikk/CVE-2025-32432

CraftCMS RCE Checker (CVE-2025-32432)

★ 10 · 2025-04-27
CTY-Research-1/CVE-2025-32432-PoC
★ 7 · 2025-08-29
P34NUT2/CVE-2025-32432-exploit-by-P34NUT

Reliable CVE-2025-32432 pre-auth RCE exploit for Craft CMS 3.x/4.x/5.x, works where other public PoCs fail

★ 7 · 2026-09-17
c0gnit00/CVE-2025-32432

Exploit, POC for CVE-2025-32432, CraftCMS2Shell

★ 4 · 2026-07-21
bambooqj/CVE-2025-32432

AI修复生成的CVE-2025-32432的poc

★ 2 · 2025-09-23
cd-ratel/CVE-2025-32432

Working PoC for CVE-2025-32432 - Craft CMS <= 5.6.16 unauthenticated RCE via Yii2 PhpManager gadget + nginx access.log poisoning

★ 2 · 2026-05-15
PsyGuy007-sys/craftcms-cve-2025-32432-rce

Craft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research

★ 1 · 2026-08-05
PoCs 1 ★ 2 Last push 2026-09-17 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 1 repositories
yzy0okrkv1hngo0r/CVE-2026-55781-poc

Unbounded memory allocation in NanaZip's UFS handler via an attacker-controlled `fs_bsize` field.

★ 2 · 2026-09-17
CVE-2019-11447
MULTI PoC
PoCs 7 ★ 9 Last push 2026-09-17 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 7 repositories
thewhiteh4t/cve-2019-11447

CutePHP Cute News 2.1.2 RCE PoC

★ 9 · 2021-03-18
khuntor/CVE-2019-11447-EXP

CuteNews Avatar 2.1.2 Remote Code Execution Vulnerability

★ 1 · 2020-10-30
CRFSlick/CVE-2019-11447-POC

CuteNews 2.1.2 - CVE-2019-11447 Proof-Of-Concept

★ 1 · 2024-02-11
mt-code/CVE-2019-11447

Exploits CuteNews 2.1.2 via poor file upload checks used when uploading an avatar image leading to RCE.

★ 0 · 2020-10-20
ColdFusionX/CVE-2019-11447_CuteNews-AvatarUploadRCE

Exploit Code for CVE-2019-11447 aka CuteNews 2.1.2 Avatar upload RCE (Authenticated)

★ 0 · 2021-03-17
capivara-research/WordPress-Path-Traversal-CVE-2019-11447

CPTS HackTheBox - Penetration Test Report: WordPress Path Traversal CVE-2019-11447

★ 0 · 2026-09-17
PoCs 2 ★ 2 Last push 2026-09-17 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 2 repositories
Wrin9/CVE-2021-43287

CVE-2021-43287_GoCD_fileread_POC_EXP

★ 2 · 2022-05-16
HigorGabrielDCF/GoCD_PoC_Supply_Chain_Attack

CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290

★ 2 · 2026-09-17
PoCs 2 ★ 0 Last push 2026-09-16 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 2 repositories
pvharmo2/gha-lab-733c168b88

Authorized security-research lab reproducing CVE-2026-44246 (GHSA-63mx-j37w-gh59): prompt injection via verbatim issue title/body inlining into the claude-code…

★ 0 · 2026-09-06
sushant-me/agentic-workflow-injection

Reproducible vulnerable/fixed fixtures for agentic workflow injection in GitHub Actions (CVE-2026-44246), plus measured detector coverage

★ 0 · 2026-09-16
PoCs 1 ★ 0 Last push 2026-09-16 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 1 repositories
ShadowForge-Cyber/CVE-2026-12944

Langflow 1.10.0 urllib SSRF

★ 0 · 2026-09-16
PoCs 2 ★ 17 Last push 2026-09-16 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 2 repositories
karollooool/CVE-2026-83991-writeup-and-poc

CVE-2026-83991: Windows Cloud Files access-check bypass

★ 17 · 2026-09-16
PoCs 2 ★ 1 Last push 2026-09-16 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 2 repositories
bruno-1337/CVE-2023-23946-POC

Explanation and POC of the CVE-2023-23946

★ 1 · 2023-09-13
tralsesec/CVE-2023-23946

Original standalone Proof-of-Concept exploit for CVE-2023-23946 (Git path traversal via crafted patches in git-apply).

★ 0 · 2026-09-16
PoCs 1 ★ 2 Last push 2026-09-16 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 1 repositories
ambionics/spip-exploits

spip exploits for CVE-2026-72708, CVE-2026-72709, CVE-2026-72710

★ 2 · 2026-09-16
PoCs 2 ★ 0 Last push 2026-09-16 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 2 repositories
cklinisme/doris-spark-connector-cve

Unofficial Apache Doris Spark connector 26.1.0 security fork for Java / Spark 3.5.1 / Scala 2.12; patched shaded Jackson for CVE-2026-54512.

★ 0 · 2026-09-16
< Prev Page 30 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.